Ransom.LockerGoga

ThreatDown is now the name of the Malwarebytes line of business products. References to Malwarebytes below reflect the amazing technology used to first identify the threat.

Short bio

Ransom.LockerGoga is Malwarebytes’ detection name for a ransomware that is primarily used in targeted, and very disruptive attacks.

Type of infection

Ransomware is a form of malware that locks you out of your device and/or encrypts your files, then forces you to pay a ransom to get them back. Ransom.LockerGoga is typically delivered by a targeted attack using login credentials that the threat actor somehow got hold of.

Malicious behavior

Ransom.LockerGoga encrypts files on the affected system and adds the .locked extension to the encrypted files. Ransom.LockerGoga shows a ransom note called README_LOCKED.txt

Users of affected systems may also find themselves locked out because their login credentials were changed.

Aftermath

Besides the encrypted files of the filetypes:

.doc, .dot, .docx, .docb, .dotx, .wkb, .xlm, .xml, .xls, .xlsx, .xlt, .xltx, .xlsb, .xlw, .ppt, .pps, .pot, .ppsx, .pptx, .posx, .potx, .sldx, .pdf, .db, .sql, .cs, .ts, .js, and .py

users my find that they have been locked out of their systems because their credentials were changed by the threat actor.

Protection

Malwarebytes blocks Ransom.LockerGoga

Business remediation

Malwarebytes can detect and remove Ransom.LockerGoga on business machines without further user interaction. To remove Ransom.LockerGoga using Malwarebytes business products, follow the instructions below.

Home remediation

Malwarebytes can detect and remove Ransom.LockerGoga without further user interaction.

  • Please download Malwarebytes to your desktop.
  • Double-click MBSetup.exe and follow the prompts to install the program.
  • When your Malwarebytes for Windows installation completes, the program opens to the Welcome to Malwarebytes screen.
  • Click on the Get started button.
  • Click Scan to start a Threat Scan.
  • Click Quarantine to remove the found threats.
  • Reboot the system if prompted to complete the removal process.

Take note, however, that removing this ransomware does not decrypt your files. You can only get your files back from backups you made before the infection happened.